Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: cipher.exe Overwrites Deleted Data Using /w
Flags Windows cipher.exe runs with /w: to overwrite deleted data on disk.
sigmaWindowsmedium2021-12-26Windows PowerShell Wallpaper Replacement via Registry and SystemParametersInfo
Identifies PowerShell script blocks that modify the HKCU Desktop\WallPaper setting to replace a user’s wallpaper.
sigmaWindowslow2021-12-26Windows PowerShell Script: Remove Account From Domain Admin Group via Remove-ADGroupMember
Alerts on PowerShell commands removing specified members via Remove-ADGroupMember, potentially disrupting Domain Admin access.
sigmaWindowsmedium2021-12-26Java keytool Spawns System Shells or Scripting Utilities on Windows
Alerts when Java keytool.exe spawns command and script execution binaries like cmd.exe or PowerShell on Windows.
sigmaWindowshigh2021-12-22Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Alerts on Windows process executions using filenames that match common Sysinternals tools to indicate potential binary impersonation.
sigmaWindowsmedium2021-12-20Suspicious Windows Process Creation as SYSTEM User with Likely Credential/Defense Evasion Commands
Flags SYSTEM-context process executions on Windows that include suspicious tool names or command-line patterns such as PowerShell/Mimikatz indicators.
sigmaWindowshigh2021-12-20Windows Registry and PowerShell Modification of ms-settings Protocol Handler
Flags reg.exe or PowerShell registry edits that alter the ms-settings protocol handler open command path.
sigmaWindowsmedium2021-12-20Windows sqlcmd.exe Credential Dump Query Against VeeamBackup dbo
Alerts on sqlcmd.exe running a query targeting the VeeamBackup dbo Credentials table to dump sensitive credentials.
sigmaWindowshigh2021-12-20Windows: Detect sc.exe Service Creation with DACL Modification (sdset DCLCWPDTSD)
Alerts on sc.exe sdset usage with DCLCWPDTSD, suggesting permission changes to hide or impede service removal.
sigmaWindowshigh2021-12-20Windows reg.exe Credential Enumeration via Registry Query (HKLM/HKCU)
Flags reg.exe registry queries (REG_SZ, recursive) focused on HKLM/HKCU and PuTTY Sessions to enumerate credential material.
sigmaWindowsmedium2021-12-20PowerShell Credential Manager enumeration via vaultcmd /listcreds
Flags PowerShell using vaultcmd /listcreds to enumerate Windows/Web credential manager stored entries.
sigmaWindowsmedium2021-12-20PowerShell Credential Manager Credential Dump via Script Block Text Matching (Windows)
Alerts on PowerShell script blocks that invoke Windows Credential Manager credential retrieval functions.
sigmaWindowsmedium2021-12-20PowerShell Credential Discovery via Recursive File Search and Select-String
Flags PowerShell script blocks that recursively list files and run select-string pattern searches, indicative of credential hunting.
sigmaWindowsmedium2021-12-19Windows: Process Execution of PsLogList with Event Log Dump/Export Flags
Detects PsLogList executions aimed at Security/Application/System logs with dump/export/clear command-line switches.
sigmaWindowsmedium2021-12-18Windows CleanWipe-Like PUA Execution via System Tool Uninstall Switches
Flags Windows processes launching CleanWipe-like removal tools with uninstall parameters for security impairment investigation.
sigmaWindowshigh2021-12-18Windows Process Creation: Advanced Port Scanner PUA Execution via /portable /lng
Flags Windows launches of Advanced Port Scanner with /portable and /lng parameters.
sigmaWindowsmedium2021-12-18Windows Process Command-Line Flags Indicating Auditpol Policy Tampering
Detects auditpol runs with flags that disable key audit categories, indicating potential audit policy tampering for defense impairment.
sigmaWindowshigh2021-12-18Windows: java.exe Parent Spawning cmd/powershell/bash Processes
Alerts when java.exe launches cmd, PowerShell, or bash on Windows, a potential sign of command execution.
sigmaWindowsmedium2021-12-17Windows: Alert on Java.exe Spawning Suspicious System and Script Binaries
Triggers when java.exe launches a child utility commonly abused for command execution and administration.
sigmaWindowshigh2021-12-17Windows Sysmon Discovery Attempt via Findstr.exe Default Driver Altitude (385201)
Alerts on findstr/find.exe executions containing 385201, consistent with using Sysmon default driver altitude for discovery.
sigmaWindowshigh2021-12-16